Live data from Hacker News

Recent 'MFA Bombing' Attacks Targeting Apple Users

krebsonsecurity.com

1–10 of 233 posts

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#2
I’m still disappointed by Apples implementation of security keys. I want to be able to prevent all 2FA methods other than security keys, but it still seems possible in certain flows to authorise a new login with another iOS device making it vulnerable to this attack.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#4
Yet another reason why phone number verification is the most insecure way to verify users and it doesn't matter if a company like Apple is using it or your bank using so called 'Military grade encryption'. The point still stands [4] with countless examples [0] [1] [2] [3].

Unless you want your users to be SIM swapped, there is no reason to use phone numbers for logins, verification and 2FA.

[0] https://news.ycombinator.com/item?id=36133030

[1] https://news.ycombinator.com/item?id=34447883

[2] https://news.ycombinator.com/item?id=27310112

[3] https://news.ycombinator.com/item?id=29254051

[4] https://www.issms2fasecure.com

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#5
post #4

Yet another reason why phone number verification is the most insecure way to verify users and it doesn't matter if a company like Apple is using it or your bank using so called 'Military grade encryption'. The point still stands [4] with countless examples [0] [1] [2] [3]. Unless you want your users to be SIM swapped, there is no reason to use phone numbers for logins, verification and 2FA. [0] https://news.ycombinat…

This has nothing to do with SIM swapping or phone numbers.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#6
post #4

Yet another reason why phone number verification is the most insecure way to verify users and it doesn't matter if a company like Apple is using it or your bank using so called 'Military grade encryption'. The point still stands [4] with countless examples [0] [1] [2] [3]. Unless you want your users to be SIM swapped, there is no reason to use phone numbers for logins, verification and 2FA. [0] https://news.ycombinat…

What's the recommended alternative for mere mortal hackers?

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#7
post #4

Yet another reason why phone number verification is the most insecure way to verify users and it doesn't matter if a company like Apple is using it or your bank using so called 'Military grade encryption'. The point still stands [4] with countless examples [0] [1] [2] [3]. Unless you want your users to be SIM swapped, there is no reason to use phone numbers for logins, verification and 2FA. [0] https://news.ycombinat…

This has nothing to do with SIM swapping or phone numbers.

TFA talks specifically about a victim buying a brand new phone, registering a new appleid, and getting MFA bombed immediately when putting in his old SIM...

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#8
"recent"?

This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple.

As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone coercing/subverting Apple, be it law enforcement or a hacker) power to get access to our accounts. This obviously stopped the attackers dead in their track.

For similar reasons I set up advanced data protection as soon as it was available and disabled web access. Only trusted devices get to see our data, and only trusted devices get to enroll a new device.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#9
post #4

Yet another reason why phone number verification is the most insecure way to verify users and it doesn't matter if a company like Apple is using it or your bank using so called 'Military grade encryption'. The point still stands [4] with countless examples [0] [1] [2] [3]. Unless you want your users to be SIM swapped, there is no reason to use phone numbers for logins, verification and 2FA. [0] https://news.ycombinat…

This has nothing to do with SIM swapping or phone numbers.

>phone numbers.

On the official Apple reset form, the "phone number" is one of the id options the hackers can use to MFA bomb the target:

https://iforgot.apple.com/password/verify/appleid

The gp proposes a different "private identification string" that's not public. Public IDs such as "email address" or "phone number" are susceptible to what this article is talking about.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#10
post #4

Yet another reason why phone number verification is the most insecure way to verify users and it doesn't matter if a company like Apple is using it or your bank using so called 'Military grade encryption'. The point still stands [4] with countless examples [0] [1] [2] [3]. Unless you want your users to be SIM swapped, there is no reason to use phone numbers for logins, verification and 2FA. [0] https://news.ycombinat…

This has nothing to do with SIM swapping or phone numbers.

That is not true. Please read article, he even bought new phone, and this did not stop attack, because of same phone number. I woul not even call this MFA attack, as they did not need his password. It is more like recovery password attack.
Post reply on HN